Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95h4-w6j8-2rp8

Опубликовано: 02 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow MadeYouReset HTTP/2 DDoS Vulnerability

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.38.Final

2.2.38.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0.Alpha1, < 2.3.20.Final

2.3.20.Final

EPSS

Процентиль: 38%
0.00165
Низкий

7.5 High

CVSS3

Дефекты

CWE-404
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
redhat
2 месяца назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVSS3: 7.5
debian
2 месяца назад

A flaw was found in Undertow where malformed client requests can trigg ...

EPSS

Процентиль: 38%
0.00165
Низкий

7.5 High

CVSS3

Дефекты

CWE-404
CWE-770